---
title: 'Topic: aiohttp'
canonical_url: https://portal.chinng-lab-srv.dev/topics/aiohttp.md
content_kind: topic
updated_at: '2026-07-16T06:46:07Z'
---

# Topic: aiohttp

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/aiohttp.md
- Last updated: 2026-07-16T06:46:07Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=aiohttp
- MCP: portal_search(q="aiohttp")

## Related categories

- security/library

## Related entities

- monitoring framework
- TLS_CERTIFICATES
- Server Card
- chrome_settings_overrides
- payload.json
- response.json
- Computational Resources (technology
- area
- https://deploymentsafety.openai.com/gpt-5-6/gpt-5-6.pdf
- patch queue
- declarativeNetRequest
- Max Planck
- Aid worker Mohammed al-Wahidi had become a prominent humanitarian figure during the Israel-Hamas war...
- τ²-bench airline domain
- Ghost
- HashTag
- earlyappleleaks
- FlyingCookie
- AND CaaaLL
- latecapitalism

## Latest articles

- [CVE-2026-54276 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-dcbe9c.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This…
- [CVE-2026-54278 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-bacc5b.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chun…
- [CVE-2026-54277 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-b8656e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using…
- [CVE-2026-54280 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-46393e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a pa…
- [CVE-2026-54279 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-1775ac.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() l…
- [CVE-2026-54275 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260711-347a7c.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an applica…
- [CVE-2026-54273 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-e1a21e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able…
- [CVE-2026-54274 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-cf3c24.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual…
- [CVE-2026-50269 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-ad7e36.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to i…
- [CVE-2026-54274: aiohttp: Incomplete websocket frame payloads bypass memory limits](https://portal.chinng-lab-srv.dev/security/library/security-20260711-ae9caf.md): aiohttp: Incomplete websocket frame payloads bypass memory limits
- [CVE-2026-54275: aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections](https://portal.chinng-lab-srv.dev/security/library/security-20260711-62a631.md): aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
- [CVE-2026-54280: aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a86bd4.md): aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
- [CVE-2026-54273: aiohttp: HTTP/1 Pipelined Requests Queue Without Limit](https://portal.chinng-lab-srv.dev/security/library/security-20260711-f88f5e.md): aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
- [CVE-2026-54278: aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup](https://portal.chinng-lab-srv.dev/security/library/security-20260711-724d0b.md): aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
- [CVE-2026-54277: aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines](https://portal.chinng-lab-srv.dev/security/library/security-20260711-519445.md): aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
- [CVE-2026-54276: aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a38446.md): aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
- [CVE-2026-54279: aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence](https://portal.chinng-lab-srv.dev/security/library/security-20260711-546e87.md): aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
- [CVE-2026-50269: aiohttp: CRLF injection in multipart headers](https://portal.chinng-lab-srv.dev/security/library/security-20260711-149a61.md): aiohttp: CRLF injection in multipart headers
- [CVE-2026-47265: AIOHTTP is vulnerable to cross-origin redirect with per-request cookies](https://portal.chinng-lab-srv.dev/security/library/security-20260711-50a642.md): AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
- [CVE-2026-34993: AIOHTTP is Vulnerable to Deserialization of Untrusted Data](https://portal.chinng-lab-srv.dev/security/library/security-20260711-900f4a.md): AIOHTTP is Vulnerable to Deserialization of Untrusted Data
- [CVE-2026-47265 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-ce4cf5.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin r…
- [CVE-2026-34993 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-ce6a2b.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most appli…
- [CVE-2026-34525: AIOHTTP accepts duplicate Host headers](https://portal.chinng-lab-srv.dev/security/library/security-20260711-1e8734.md): AIOHTTP accepts duplicate Host headers
- [CVE-2026-34520: AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass](https://portal.chinng-lab-srv.dev/security/library/security-20260711-f48359.md): AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
- [CVE-2026-34519: AIOHTTP has HTTP response splitting via \r in reason phrase](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d9d1cc.md): AIOHTTP has HTTP response splitting via \r in reason phrase
- [CVE-2026-34518: AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect](https://portal.chinng-lab-srv.dev/security/library/security-20260711-98fb3e.md): AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
- [CVE-2026-34517: AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d6808c.md): AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
- [CVE-2026-34516: AIOHTTP has a Multipart Header Size Bypass](https://portal.chinng-lab-srv.dev/security/library/security-20260711-948d77.md): AIOHTTP has a Multipart Header Size Bypass
- [CVE-2026-34515: AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows](https://portal.chinng-lab-srv.dev/security/library/security-20260711-e9b025.md): AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
- [CVE-2026-34514: AIOHTTP has CRLF injection through multipart part content type header construction](https://portal.chinng-lab-srv.dev/security/library/security-20260711-100e97.md): AIOHTTP has CRLF injection through multipart part content type header construction
- [CVE-2026-34513: AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector](https://portal.chinng-lab-srv.dev/security/library/security-20260711-812ce3.md): AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
- [CVE-2026-34520 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-4bc02e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in res…
- [CVE-2026-34519 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-4bb846.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject e…
- [CVE-2026-34518 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-187376.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but re…
- [CVE-2026-34525 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-1848ab.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
- [CVE-2026-34517 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-b423cc.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking clie…
- [CVE-2026-34514 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-aee7ef.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra…
- [CVE-2026-34515 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-9ce7c4.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This…
- [CVE-2026-34513 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-667ec2.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situ…
- [CVE-2026-34516 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-0a3800.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory tha…
- [CVE-2026-22815 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-e7b10d.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This i…
- [CVE-2026-22815: aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage](https://portal.chinng-lab-srv.dev/security/library/security-20260711-e0b270.md): aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
